
List all posts by Authors, nested Categories and Titles Security & Risk Analysis
wordpress.org/plugins/list-all-posts-by-authors-nested-categories-and-titlesThis plugin lists all posts by Author, nested Categories and Title, allowing to place the lists in any page.
Is List all posts by Authors, nested Categories and Titles Safe to Use in 2026?
Generally Safe
Score 85/100List all posts by Authors, nested Categories and Titles has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'list-all-posts-by-authors-nested-categories-and-titles' plugin version 2.9.0 demonstrates some good security practices, including 100% proper output escaping and the use of prepared statements for all SQL queries, which are crucial for preventing common web vulnerabilities. The absence of file operations and external HTTP requests further reduces the potential attack vectors.
However, the plugin has a notable security concern with one unprotected AJAX handler, representing a significant entry point that could be exploited if malicious input is not properly handled. While the static analysis found no critical or high severity taint flows and a complete absence of raw SQL queries, the existence of an unprotected AJAX endpoint remains a primary risk. The vulnerability history shows one past medium severity Cross-Site Scripting (XSS) vulnerability, which, although currently patched, indicates a potential weakness in input sanitization that could reappear if not carefully managed in future updates.
In conclusion, the plugin has strengths in its output handling and database query practices. Nevertheless, the unprotected AJAX handler is a direct security concern that requires immediate attention. The past XSS vulnerability also suggests a need for continued vigilance regarding input validation. The overall security posture is fair, with a critical area for improvement in access control for its entry points.
Key Concerns
- Unprotected AJAX handler present
- Past medium severity XSS vulnerability
List all posts by Authors, nested Categories and Titles Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
List all posts by Authors, nested Categories and Title <= 2.8.2 - Cross-Site Scripting
List all posts by Authors, nested Categories and Titles Release Timeline
List all posts by Authors, nested Categories and Titles Code Analysis
Output Escaping
Data Flow Analysis
List all posts by Authors, nested Categories and Titles Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
List all posts by Authors, nested Categories and Titles Maintenance & Trust
Maintenance Signals
Community Trust
List all posts by Authors, nested Categories and Titles Alternatives
Author Recent Posts
author-recent-posts
Author Recent Posts shows recent posts by an author on the posts written by the author as a responsive widget. This plugin is useful for multi-author …
Authors Posts Widget
authors-posts-widget
Authors posts widget with blogger style.
Latest Posts by Author
latest-posts-by-author
Displays an unordered list of an author's latest posts.
Top Authors
top-authors
A highly customizable widget that allows you to display the top authors of your website easily.
Protected Post Personalizer
protected-post-personalizer
This plugin is a simple one, but good at what it does. It changes three elements of protected posts to make them more friendly to visitors.
List all posts by Authors, nested Categories and Titles Developer Profile
2 plugins · 720 total installs
How We Detect List all posts by Authors, nested Categories and Titles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.